- Products
- Learn
- Local User Groups
- Partners
- More
Step Into the Future of
AI-Powered Cyber Security
What's New in R82.10?
Register HereWhen the Agents Attack
A Live Look at Agentic Exposure Validation
AI Security Masters E8:
Claude Mythos: New Era in Cyber Security
CheckMates Go:
CheckMates Fest
Hi all,
Does anyone know what the limit is for Custom Threat Feed entries? Just curious as I have been playing around with IP & MD5 feeds. Is it by file size or number of entries?
Thanks
Rahul
Hey bud,
Below link will help. Appears its 1024 per observable and 2 million observable limit.
Andy
Not quite accurate 😉
Prior to R81.20, we cannot provide an exact limit since it depends on the IOCs and other blades in use.
However, it is significantly lower than the 2 million IOCs we tested in R81.20, which had new infrastructure created to support a large number of IoCs. (Actual limit depends on available memory)
Hey bud,
Below link will help. Appears its 1024 per observable and 2 million observable limit.
Andy
Perfect thanks Andy!!
It goes without saying...FYFOC ; - )
Not quite accurate 😉
Prior to R81.20, we cannot provide an exact limit since it depends on the IOCs and other blades in use.
However, it is significantly lower than the 2 million IOCs we tested in R81.20, which had new infrastructure created to support a large number of IoCs. (Actual limit depends on available memory)
Fair enough :). I just quoted numbers from that post.
Andy
Thanks Phoneboy,
If this is memory dependent I assume you'd have to be at a high memory usage to start running into issues, just out of curiousity do we know if any sort of log is generated for failed feed updates?
Edit: Looks like the notes for Custom Threat Intelligence show:
Thanks,
Rahul
Appears as per below:
https://support.checkpoint.com/results/sk/sk132193
Observables of IP addresses and IP Ranges can hold IPv4 values only. In R81 and higher versions IPV6 is supported as well.
MD5, SHA1, SHA256 observables cannot be enforced by Anti-Bot Blade. If user does not enable Anti-Virus blade, there will be no enforcement.
For R80.20SP, a Jumbo Hotfix Accumulator installation is required.
Inbound traffic to a host behind the gateway does not get blocked, e.g: IP that is on the feed, sends ICMP Request to a host behind the gateway. This traffic does not get blocked.
In R81 and higher versions, this traffic is blocked.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 12 | |
| 6 | |
| 5 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 |
Tue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionTue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleTue 16 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point SASE | Internet Access Optimization & Performance TuningThu 18 Jun 2026 @ 10:00 AM (CEST)
The Cloud Architects Series: Check Point WAF - The Next Generation of AI powered protectionTue 23 Jun 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point Cloud Firewall | Securing all of your clouds: Art of the possibleThu 25 Jun 2026 @ 10:00 AM (PDT)
AI Security Masters E10: READY OR NOT: Securing the AI Enterprise 2/5 - AI Red TeamingAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY